Invision Power Board 'core.php' PHP Code Execution Vulnerability
BID:56288
Info
Invision Power Board 'core.php' PHP Code Execution Vulnerability
| Bugtraq ID: | 56288 |
| Class: | Input Validation Error |
| CVE: |
CVE-2012-5692 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 25 2012 12:00AM |
| Updated: | Nov 14 2012 11:40AM |
| Credit: | EgiX |
| Vulnerable: |
Invision Power Services Invision Power Board 3.3.1 Invision Power Services Invision Power Board 3.3 Invision Power Services Invision Power Board 3.2.3 Invision Power Services Invision Power Board 3.2.2 Invision Power Services Invision Power Board 3.2.1 Invision Power Services Invision Power Board 3.2 Invision Power Services Invision Power Board 3.1.4 Invision Power Services Invision Power Board 3.1.3 Invision Power Services Invision Power Board 3.1.2 |
| Not Vulnerable: | |
Discussion
Invision Power Board 'core.php' PHP Code Execution Vulnerability
Invision Power Board is prone to a vulnerability that lets remote attackers execute arbitrary code.
Attackers can exploit this issue to execute arbitrary PHP code within the context of the affected webserver process.
Invision Power Board versions 3.1.x, 3.2.x, and 3.3.x are vulnerable.
Invision Power Board is prone to a vulnerability that lets remote attackers execute arbitrary code.
Attackers can exploit this issue to execute arbitrary PHP code within the context of the affected webserver process.
Invision Power Board versions 3.1.x, 3.2.x, and 3.3.x are vulnerable.
Exploit / POC
Invision Power Board 'core.php' PHP Code Execution Vulnerability
Attackers can exploit this issue through a browser.
The following exploits are available:
Attackers can exploit this issue through a browser.
The following exploits are available:
Solution / Fix
Invision Power Board 'core.php' PHP Code Execution Vulnerability
Solution:
Vendor updates are available. Please see the references for more information.
NOTE (Nov 8, 2012): Reports indicate that the fix for this issue is incomplete.
Solution:
Vendor updates are available. Please see the references for more information.
NOTE (Nov 8, 2012): Reports indicate that the fix for this issue is incomplete.
References
Invision Power Board 'core.php' PHP Code Execution Vulnerability
References:
References:
- Invision Power Board Home Page (Invision Power Services)